Fraunhofer-Gesellschaft

Fraunhofer-Gesellschaft

Speciality: Comprehensive IT, Embedded Systems, and Automotive Security Pentesting

München, Germany 10001 employees
[01] About

Research organization based in Germany with 1,061 employees and EUR 2.2B annual revenue; provides applied research and technological development, including penetration testing services through affiliated institutes; founded in 1949, headquartered in München, Bavaria.

Die Fraunhofer-Gesellschaft ist eine der führenden Organisationen für anwendungsorientierte Forschung: Seit der Gründung 1949 stärken Fraunhofer-Institute die Wettbewerbsfähigkeit der Wirtschaft und den Innovationsraum in Deutschland und Europa. Mit ganzheitlichen Angeboten für Wirtschaft und Politik liefert Fraunhofer Lösungen für branchenübergreifenden Impact. Darüber hinaus ist die Fraunhofer-Gesellschaft ein bedeutender Standortfaktor für das Innovationsland Deutschland: Durch die Aktivitäten erhöhen sich Investitionseffekte in der Wirtschaft, erlangen Unternehmen innovationsbasierte Wettbewerbsvorteile, entstehen Arbeitsplätze, Fachkräfte werden qualifiziert und es steigt die gesellschaftliche Akzeptanz moderner Technik.
[02] Services
Provides Penetration Testing
Vulnerability Assessment
IT Security Consulting
Security Testing
Applied Research Services Across Various Industries.
[03] Certifications
ISO 9001

ISO 9001 and Cybersecurity/IT


Origin


ISO 9001 is a quality management system standard developed by the International Organization for Standardization (ISO), first published in 1987. However, it's important to note that ISO 9001 itself is not a cybersecurity or IT-specific certification—it's a general quality management standard applicable to any industry. For cybersecurity and IT specifically, ISO created ISO/IEC 27001 in 2005, which focuses on information security management systems. ISO 9001 was created to establish consistent quality management practices across organizations worldwide, while ISO/IEC 27001 was developed to address the growing need for standardized information security controls.


Industry Value


ISO 9001 is valued across industries for demonstrating an organization's commitment to quality, customer satisfaction, and continuous improvement, which can indirectly support IT operations. For actual cybersecurity and IT security certification, ISO/IEC 27001 is the recognized standard, valued because it provides a systematic approach to managing sensitive information, demonstrates due diligence to clients and stakeholders, and is often required for government contracts or business partnerships. ISO/IEC 27001 certification signals that an organization has implemented internationally recognized security controls and risk management processes, making it essential for building trust in an increasingly security-conscious business environment.

ISO/IEC 17025
ISO 50001

ISO 50001 - Energy Management System


Origin and Development


ISO 50001 was developed and published by the International Organization for Standardization (ISO) in June 2011, with a significant revision released in 2018. The standard was created in response to growing global concerns about energy consumption, climate change, and the need for organizations to manage their energy use more effectively. It provides a framework for establishing, implementing, maintaining, and improving an energy management system, enabling organizations to systematically reduce their energy consumption, improve energy efficiency, and decrease their overall environmental footprint.


Value to the Penetration Testing and Cybersecurity Industry


For penetration testing and cybersecurity companies, ISO 50001 certification demonstrates corporate responsibility and operational maturity beyond their core technical services. As data centers, testing laboratories, and security operations centers consume significant amounts of energy to power servers, cooling systems, and continuous monitoring infrastructure, this certification shows clients that the organization manages resources efficiently and maintains sustainable business practices. Cybersecurity firms reference ISO 50001 to distinguish themselves in competitive bids, particularly when dealing with government contracts or environmentally-conscious enterprises that evaluate vendors on comprehensive corporate governance criteria. The certification signals to potential clients that the company maintains systematic management processes and is committed to continuous improvement—qualities that parallel the rigor expected in their security testing methodologies.

TISAX

TISAX: Trusted Information Security Assessment Exchange


Origin


TISAX (Trusted Information Security Assessment Exchange) was created by the ENX Association (European Network Exchange) in 2017 at the request of the German automotive industry, specifically the VDA (Verband der Automobilindustrie - German Association of the Automotive Industry). The certification was developed to address the automotive sector's need for a standardized, mutual recognition framework for information security assessments. It was created to reduce the burden of multiple audits on suppliers, as automotive manufacturers were each conducting their own security assessments of shared suppliers, leading to duplication and inefficiency.


Industry Importance


TISAX has become essential for companies working with the automotive industry, particularly in Europe, as many major manufacturers now require it from their suppliers and partners. The certification provides a trusted, industry-recognized validation of a company's information security practices, protecting sensitive data such as intellectual property, product designs, and business information. Its importance stems from the mutual recognition principle—once a company achieves TISAX certification, the results are shared across participating organizations, eliminating redundant audits and creating efficiency while maintaining high security standards. For suppliers, TISAX certification has become virtually mandatory to maintain or establish business relationships with automotive OEMs and tier-1 suppliers.

[05] Notable Clients
  • BMW AG
  • Bosch Sicherheitssysteme GmbH
  • Carl Zeiss MicroImaging GmbH
  • Carl Zeiss Vision GmbH
  • CISCO Systems GmbH
  • Citibank Privatkunden AG & Co. KGaA
  • Daimler AG
  • Deutsche Apotheker- und Ärztebank eG
  • Deutsche Bank AG
  • Deutsche Telekom Laboratories
  • Deutsche Telekom Technischer Service GmbH
  • F. Hoffmann-La Roche Ltd.
  • FESTO AG & Co. KG
  • Fujitsu Siemens Computers GmbH
  • Herbert Waldmann GmbH & Co. KG
  • HOCHTIEF Aktiengesellschaft
  • Hugo Boss AG
  • IBM Deutschland GmbH
  • IDS Scheer AG
  • Intel GmbH
  • Mercedes-Benz Bank AG
  • Microsoft Deutschland GmbH
  • Novartis Deutschland GmbH
  • Océ Deutschland GmbH
  • Philips GmbH
  • Porsche AG
  • Robert Bosch GmbH
  • Santander Consumer Bank AG
  • Siemens Enterprise Communications GmbH & Co. KG
  • Steigenberger Hotels AG
  • ThyssenKrupp AG
  • TRUMPF GmbH + Co. KG
  • T-Systems Enterprise Services GmbH
  • Villeroy & Bosch AG
  • Vitra GmbH
  • Vivantes – Netzwerk für Gesundheit GmbH
  • Volkswagen AG
  • Volkswagen Bank GmbH
  • Wincor Nixdorf International GmbH